Live data from Hacker News

1Password X: A look at the future of 1Password in the browser

blog.agilebits.com

121–130 of 181 posts

Re: 1Password X: A look at the future of 1Password in the browser

#121
post #111

Earlier quoted context omitted.

What part is actually hosted here? Do they store opaque encrypted blobs and pass those around, or can they see the actual secrets too?

Disclosure: I work for AgileBits, makers of 1Password We outline the entirety of how this works in our white paper: https://1pw.ca/whitepaper We cannot tell what your data is. It's encrypted on your device using keys that only you know. Then we store it on our side on the server. The unique solution of using your Master Password and your Secret Key, makes brute forcing the data on our server an incredibly expensive j…

All it would take for 1Password to decrypt our entire vault is for 1Password to push out a software update that simply made it so that the client app uploaded the keys to 1Password's servers after the user typed it in. Without 1Password releasing their source code, end users would have no idea if such an update ever took place. We just have to trust 1Password as a company. Well, if we already trust 1Password as a company, what's the point of even using encryption? Might as well just store it in plain text in a database on your servers and trust that your employees won't look at them!

Without open source auditing of all clients and md5 checksums of compiled binaries, security is nothing more than an illusion.

Re: 1Password X: A look at the future of 1Password in the browser

#122
post #30

Ouch! I just switched to Firefox 57 and I can't use this new feature! Shouldn't the WebExtension be portable across both browsers with minimal work with Firefox 57?

Disclosure: I work for AgileBits, makers of 1Password

Making extensions cross browser can still be a bit difficult. Our focus here was to get something readily available for a browser that was in high demand on platforms that we were getting a lot of requests for (Linux and Chrome OS).

I believe browser support will expand over time with this extension, it's just that we didn't want multiple browsers slow our progress or prevent us from doing cool new things.

Give it some time and I anticipate we'll see browser support expand.

Kyle

AgileBits

Re: 1Password X: A look at the future of 1Password in the browser

#123

s/the browser/Chrome Hey 1Password, make this available for Firefox too. It should be relatively easy to port with WebExtensions API, since it looks like a toolbar popup.

Disclosure: I work for AgileBits, makers of 1Password

I posted this elsewhere, just pasting here since it's the same question/concern and gets the same answer :)

Making extensions cross browser can still be a bit difficult. Our focus here was to get something readily available for a browser that was in high demand on platforms that we were getting a lot of requests for (Linux and Chrome OS).

I believe browser support will expand over time with this extension, it's just that we didn't want multiple browsers slow our progress or prevent us from doing cool new things. Give it some time and I anticipate we'll see browser support expand.

Kyle

AgileBits

Re: 1Password X: A look at the future of 1Password in the browser

#124

I’ve been using 1Password for years, mainly because the data stays local. If they decide to go full cloud-mode I’m switching to something else or just write my own cli password manager.

Disclosure: I work for AgileBits, makers of 1Password

We've already announced that 1Password 7 for Mac will be available via standalone licenses, and 1Password 7 for Windows will offer standalone vaults and be available via a standalone license model.

So nothing is changing in that regard. Our 1Password.com is the default solution we send our users to but standalone vaults are an option for those that wish to continue down that path.

Kyle

AgileBits

Re: 1Password X: A look at the future of 1Password in the browser

#125
post #113

Earlier quoted context omitted.

Disclosure: I work for AgileBits, makers of 1Password I'm sorry you feel that way. What makes you think we're pushing you aside? We are still introducing features in 1Password 6 for Mac, and 1Password 7 for iOS that work for both our hosted solution and our standalone users. We are able to offer a lot of newer features to our 1Password.com membership users because that solution opens a lot of new possibilities. But w…

I'm just wondering, does your period subscription license also include your "stand-alone" software?

It does.

So if you purchase a subscription, you'll sign into an account for 1Password in the app. The presence of an active account (one that's in paid status, or trial) will unlock the standalone licensed portion of the application. So you can freely use those features to your hearts content.

At least, that's how it works for Mac and iOS. I contribute to those teams specifically on the development side so I'm most familiar there, I'm not sure I know enough about Android to comment there and be accurate. If you need to know about Android I can find out though. Regarding Windows, not currently because version 6 is 1Password.com only, however, version 7 will add standalone vaults and a traditional license model, I anticipate it will copy our Mac application but until it ships I can't guarantee anything.

Kyle

AgileBits

Re: 1Password X: A look at the future of 1Password in the browser

#126
post #111

Earlier quoted context omitted.

Disclosure: I work for AgileBits, makers of 1Password We outline the entirety of how this works in our white paper: https://1pw.ca/whitepaper We cannot tell what your data is. It's encrypted on your device using keys that only you know. Then we store it on our side on the server. The unique solution of using your Master Password and your Secret Key, makes brute forcing the data on our server an incredibly expensive j…

All it would take for 1Password to decrypt our entire vault is for 1Password to push out a software update that simply made it so that the client app uploaded the keys to 1Password's servers after the user typed it in. Without 1Password releasing their source code, end users would have no idea if such an update ever took place. We just have to trust 1Password as a company. Well, if we already trust 1Password as a com…

If that's your concern then I'm afraid there's little we can do to change your opinion and perhaps 1Password isn't the solution for you.

I don't mean to sound rude or anything like that. Just being honest.

We have had grand visions of offering portions of our source (notably the cryptographic portions) available for review, note, not open source in the sense you can use it but in a license that makes it available for review purposes.

If 1Password.com was the sole solution we offered then open sourcing the entire app would be potentially feasible because our income wouldn't rely on people compiling their own version and editing out the license code. But it makes little sense for us to make that available if modified copies can be made available removing a chunk of our income.

For what it's worth, we have over 90 people who depend on AgileBits to provide paychecks so people can support their families. That's a heavy burden when your decisions can impact that many lives. I'm just a member of our team, not a founder or owner or anything but hopefully you can recognize this side of things.

We'd like nothing more than to do whatever we can to get users to trust us but there are limits to what we can do and still keep 1Password alive.

If you absolutely have to see the code in order to trust an application then there are other options out there, but they won't provide the same level of support, features, or hands off management. These are trade offs you have to make as an individual. Only you can make those decisions for you.

Every person at AgileBits uses 1Password, and we design it knowing we will be using it and we are all passionate about wanting our data secure. If we did something to put your data at risk, we did the same thing to ourselves. Just another view of that I suppose.

Kyle

AgileBits

Re: 1Password X: A look at the future of 1Password in the browser

#127
post #103

Am I the only one in here who loves their hosted solutions? We use Teams at work and I use Family for my wife and I. It's important to me that I have access to certain passwords on my desktop, laptop and phone. These items also need to be accessible to others who should be able to view/edit. There's no way to do with without some sort of cloud solution and so the decision becomes which cloud solution. I used to use D…

I really wanted to use 1Password for Teams, I don't mind paying a subscription model, and their whitepaper on their hosted solution is really quite thorough: https://1password.com/security/ My big issue is still with the web app allowing you to unlock your vault and access your passwords. They acknowledge in the whitepaper that it's theoretically possible that an attacker could MITM your SSL connection and serve mali…

This is something we plan to tackle in the future. Probably via some sort of downloadable local copy of the web client. But it's possible we integrate it into each app somehow. It's still something I think we're trying to think through to try to get right before we act.

As it stands, the only reason you need to login to the web client is for administration purposes and sign up. After that the native clients handle the rest.

That said, as you indicated, we're aware of this potential vector of attack and acknowledge it.

Kyle

AgileBits

Re: 1Password X: A look at the future of 1Password in the browser

#128
post #63

Earlier quoted context omitted.

1Password X is a pure Chrome extension and does not rely on the native app. This has its benefits and obvious drawbacks. Some of the benefits: * Simpler installation * Support for multiple users on the same computer with Chrome user profiles * Support for Chrome OS

Is this an option for Chrome/Linux/ChromeOS users to provide a more streamlined first-use experience? The "a look at the future" and "this is just the beginning" wording in the announcement blog post implies that this is the direction that 1Password is taking as a product, and Chrome support is just the beginning. As a user who prefers a native implementation, uses local vaults, and uses Firefox, none of these advant…

I think the easiest way to look at this is as you said, another option for users.

Some enterprises don't allow their users to install applications, but do allow extensions, so this opens up that possibility.

It also brought 1Password support to two new platforms: Linux and Chrome OS.

As for this being the future. Imagine a world where from a design perspective this sets the tone. Thus, the beginning of the future.

It's a first version that has to compare itself against versions that have existed for years. Of course it can't fully replace what we have. It may for some though, I won't discount that at all.

For starters, there's no way to do Touch ID in the browser. There's no support for local vaults. There's only Chrome support, nothing for Safari or Firefox. There's a lot missing here.

But in terms of the future, this sets the visual design up for how you'll start seeing future updates on the other side of the extension fence.

So, lets go with "this isn't for you" :)

In fact, I doubt in a lot of ways that this is for people on Hacker News. A smaller number will probably find it useful though.

Kyle

AgileBits

Re: 1Password X: A look at the future of 1Password in the browser

#129
post #51

Chrome only makes this effectively useless. Considering that the entire browser market is moving to a largely unified web extension format this is not that impressive. "Everywhere Chrome works" is simply repeating the mistakes of the past, but with Chrome now instead of IE.

Disclosure: I work for AgileBits, makers of 1Password.

This was posted in a couple different similar threads so I'm pasting it here as it's a direct answer to your concern.

Making extensions cross browser can still be a bit difficult. Our focus here was to get something readily available for a browser that was in high demand on platforms that we were getting a lot of requests for (Linux and Chrome OS).

I believe browser support will expand over time with this extension, it's just that we didn't want multiple browsers slow our progress or prevent us from doing cool new things.

Give it some time and I anticipate we'll see browser support expand.

Kyle

AgileBits

Post reply on HN